PT-2024-9118 · Hewlett Packard · Hpe Autopass License Server

Published

2024-11-25

·

Updated

2025-07-14

·

CVE-2024-51768

CVSS v3.1

8.0

High

VectorAV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Hewlett Packard Enterprise AutoPass License Server versions prior to 9.17
Description An hsqldb-related remote code execution vulnerability exists in HPE AutoPass License Server (APLS). The vulnerability is due to insufficient input validation. Exploitation may allow a remote attacker to execute arbitrary code.
Recommendations Update Hewlett Packard Enterprise AutoPass License Server to version 9.17 or later.

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2024-10804
CVE-2024-51768
ZDI-24-1632

Affected Products

Hpe Autopass License Server